Sign in
CVE-2009-4851
CVE-2009-4851
Description
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
Impact
CVSS v2 : 5 MEDIUM
Type
CWE-264
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:N/I:P/A:N
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://secunia.com/advisories/37274
http://www.vupen.com/english/advisories/2009/3256
http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132
http://www.xoops.org/modules/news/article.php?storyid=5096
FAQ
Terms of service
Privacy policy